Show filters
142 Total Results
Displaying 11-20 of 142
Sort by:
Attacker Value
Unknown

CVE-2024-8059

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
Attacker Value
Unknown

CVE-2024-45105

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2024-44121

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does not impact the integrity and availability of the application
0
Attacker Value
Unknown

CVE-2024-42378

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
0
Attacker Value
Unknown

CVE-2024-37176

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data but may have low impacts on the integrity and availability of the application.
Attacker Value
Unknown

CVE-2024-34691

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact on integrity and no impact on the confidentiality and availability of the system.
Attacker Value
Unknown

CVE-2024-4139

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.
0
Attacker Value
Unknown

CVE-2024-4138

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.
0
Attacker Value
Unknown

CVE-2024-33002

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
0
Attacker Value
Unknown

CVE-2024-30217

Disclosure Date: April 09, 2024 (last updated February 26, 2025)
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the integrity of the application. Confidentiality and Availability are not impacted.
0